Authorities Dismantle IoT Botnet Linked to Record-Shattering 30 Tbps DDoS Campaigns
## International Law Enforcement Operation Dismantles IoT Botnets
International Law Enforcement Operation Dismantles IoT Botnets
International law enforcement agencies have successfully dismantled the command and control infrastructure of four major Internet of Things (IoT) botnets. These networks were responsible for launching Distributed Denial of Service (DDoS) attacks, reaching traffic volumes of up to 30 Terabits per second (Tbps).
By March 2026, these botnets had compromised over three million devices worldwide, including a significant number in the United States. The targeted devices were mainly IoT hardware such as digital video recorders, web cameras, and home WiFi routers.
The KimWolf and JackSkid botnets employed advanced techniques to infiltrate devices behind network firewalls, bypassing standard security measures.
According to the US Department of Justice, the botnet operators ran a "cybercrime as a service" model, leasing access to their networks to other cybercriminals. These customers utilized the networks for DDoS attacks, often demanding extortion payments from victims.
International law enforcement agencies have successfully dismantled the command and control infrastructure of four major Internet of Things (IoT) botnets.
The botnets targeted global servers and systems, including those managed by the U.S. Department of Defense Information Network (DoDIN). Private sector victims incurred significant financial losses and remediation costs.
Before being dismantled, the botnets were heavily utilized, issuing a large number of attack commands:
Aisuru: 200,000+ commands JackSkid: 90,000+ commands KimWolf: 25,000+ commands Mossad: 1,000+ commands
The operation required coordinated efforts from U.S. agencies, including the Defense Criminal Investigative Service (DCIS) and the FBI, which executed seizure warrants. In Germany and Canada, law enforcement targeted the botnet administrators.
Numerous technology companies and threat intelligence groups, such as Cloudflare, Akamai, Amazon Web Services, and The Shadowserver Foundation, contributed essential support. Their efforts led to the seizure of command and control servers, severing the connection to enslaved devices.
Based on reporting by GBHackers.
